1. Who we are and how to contact us about your information
Identifies the responsible party by registered name and registration number, gives its physical and postal address, and sets out the channel a person uses to raise a privacy query, make a request or lodge a complaint. Must also state the scope of the policy: which websites, platforms, forms and offline processes it covers.
Client to supply: the company registration number, the registered address if it differs from the Camperdown head office, and the dedicated email address or postal address to be used for privacy enquiries. Confirm whether the general info address is to be used or a separate one created.
2. Information Officer details
Names the person responsible for the organisation's compliance with POPIA and gives their contact details, together with any deputy Information Officer appointed. This is the person a data subject and the regulator deal with directly.
Client to supply: the name, position and contact details of the registered Information Officer, which POPIA requires, plus the details of any deputy Information Officer. Confirm whether the Information Officer has been registered with the Information Regulator. No name is stated on this page because none has been verified.
3. What personal information we collect
Lists the categories of personal information collected and the point at which each is collected. For an auction business this spans enquiry and valuation request forms, bidder registration, FICA verification documents such as identity documents and proof of address, banking and payment details, bidding history and transaction records, correspondence, and information gathered automatically when someone uses the website.
Client to supply: the final list of fields captured on every form on the site and in the bidder registration process, the exact FICA documents collected from individuals and from juristic persons, whether banking details are captured and stored by NSB or only by a payment provider, and whether any special personal information is collected. Whether identity numbers, images or biometric checks are used must be confirmed, since it affects the drafting.
4. Why we collect it and the lawful basis
Maps each category of information to the purpose it is used for, and to the ground that makes the processing lawful. Purposes include responding to enquiries, valuing and cataloguing assets, verifying and approving bidders, running the auction, taking payment, transferring ownership, arranging collection, and meeting reporting obligations to sellers and regulators. Must also deal separately with marketing and with the basis relied on for it.
Client to supply: confirmation of whether NSB sends marketing communications about upcoming auctions, to whom, and how consent or opt-out is captured and recorded. Attorney to allocate the lawful basis for each purpose. No basis is asserted on this page.
5. FICA and regulatory record keeping, and retention periods
Explains that verification records, transaction records and disposal documentation are kept for defined periods because of regulatory and contractual obligations, and states how long each category is held and what happens at the end of that period. Must reconcile the obligation to retain records with the obligation not to keep personal information longer than necessary.
Client to supply: NSB's internal retention schedule by record type. Retention periods must be confirmed against FICA and against the client's own policy before anything is published. Attorney to confirm the applicable statutory minimums and the deletion or de-identification process at the end of each period. No retention period is stated on this page.
6. Who we share information with
Identifies the categories of recipient and the reason information reaches each of them. For an auction business this includes payment and banking providers, online auction platform providers, transport, rigging and logistics providers, the seller whose asset was bought, professional advisers, and regulators, courts or liquidators where disclosure is required. Must state that operators processing information on NSB's behalf do so under written contract.
Client to supply: the actual list of third parties in use, including the online bidding platform, payment gateway, banking partner, CRM or email provider, hosting provider and any logistics partners routinely given buyer details. Confirm which of these are operators processing on NSB's behalf and whether written operator agreements are in place with each.
7. Cross-border transfers, if any
States whether personal information leaves South Africa, which recipients or service providers are involved, and on what basis a transfer is permitted. If nothing is transferred outside the country, the section says so plainly.
Client to supply: the hosting location of the website, the auction platform and any email, CRM or backup services in use, so it can be established whether cross-border transfer occurs at all. Attorney to draft the basis for any transfer that does occur.
8. How we secure personal information
Describes the safeguards applied to personal information in general terms: access controls, staff confidentiality obligations, secure handling of verification documents, encryption in transit, and the process followed if a security compromise occurs. Should be written accurately rather than aspirationally, since it can be tested after an incident.
Client to supply: the security measures actually in place, including who has access to FICA documents, where those documents are stored, whether access is logged, and the internal process for reporting and responding to a suspected compromise. Nothing should be claimed here that NSB cannot demonstrate.
9. Your rights under POPIA
Sets out what a data subject may do: request access to the personal information held about them, request correction or deletion of information that is inaccurate, irrelevant, excessive or out of date, object to processing in the circumstances the Act allows, withdraw consent where consent is the basis relied on, and complain to the Information Regulator (South Africa) as the supervisory authority. Must give the practical route for making each request and the response process.
Client to supply: the request channel and the internal turnaround NSB commits to, the identity verification step applied before a request is actioned, and whether a request form will be published. Attorney to draft the rights wording and to confirm the Information Regulator contact details published on the page.
10. Cookies and website analytics
Explains what is set when someone visits the site, what it is used for, how long it persists and how a visitor can control it. Must cover strictly necessary items separately from analytics, advertising and remarketing, because the treatment differs.
Client to confirm which analytics or tracking tools will run on the site, including any advertising or remarketing pixels, since this determines whether a cookie consent banner is legally required and what the banner must offer. Nothing is currently asserted about what this site sets. If tracking beyond strictly necessary items is added, the consent mechanism must be built before go-live, not after.
11. Changes to this policy
States how the policy may be updated, how material changes are communicated, and how a reader can tell which version applies. Should fix a version reference and effective date at the top of the published page.
Client to supply: how changes will be notified to registered bidders and clients, whether superseded versions are archived, and the version and effective date convention to be printed at the top of the published page.